

What’s stopping the downloaded script from wiping my home directory?
What’s stopping any Makefile, build script, or executable from running rm -rf ~
? The correct answer is “nothing”. PPAs are similarly open, things are a little safer if you only use your distro’s default package sources, but it’s always possible that a program will want to be able to delete something in your home directory, so it always has permission.
Containerized apps are the only way around this, where they get their own home directory.
Actually, since ICE isn’t sending people to trial, they might be lowering the US statistic lol.
So not only are you safer from getting arrested in Iran, but you’re more likely to receive a trial.